Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 0 additions & 18 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -116,24 +116,6 @@ prod env for rate limits unless the user explicitly asks. Implementation:
`RateLimitFilter` + `ClientIpKeyResolver` (IPv6 `/64`). Docs: README and
`docker/README.md`.

## Dependabot / dependency bumps

Dependabot only edits `gradle/libs.versions.toml`. This repo enables Gradle
dependency verification (`gradle/verification-metadata.xml`), so every version
bump PR must also refresh checksums or CI fails at `:compileKotlin` with
"Dependency verification failed" across Build, Docker boot, regression, and
Cloud Build (same root cause on every Dependabot Gradle PR).

On the bump branch (after rebase onto `master`):

```bash
./gradlew --write-verification-metadata sha256 --refresh-dependencies ktlintCheck jacocoTestReport bootJar
git add gradle/verification-metadata.xml
git commit -m "Refresh Gradle verification metadata for <dep> <version>."
```

Do not merge a Dependabot Gradle PR that only touches the version catalog.

## PR / verify

Before considering work done:
Expand Down
8 changes: 5 additions & 3 deletions build.gradle.kts
Original file line number Diff line number Diff line change
Expand Up @@ -81,9 +81,11 @@ sonar {
if (System.getenv("GITHUB_ACTIONS") == "true") {
property("sonar.qualitygate.wait", "true")
}
// kotlin:S6474: checksums live in gradle/verification-metadata.xml.
// After a dependency bump, refresh with:
// ./gradlew --write-verification-metadata sha256 --refresh-dependencies ktlintCheck jacocoTestReport bootJar
// Gradle dependency verification is intentionally not used (it blocked
// every Dependabot bump), so ignore kotlin:S6474 across the project.
property("sonar.issue.ignore.multicriteria", "s6474")
property("sonar.issue.ignore.multicriteria.s6474.ruleKey", "kotlin:S6474")
property("sonar.issue.ignore.multicriteria.s6474.resourceKey", "**/*")
}
}

Expand Down
Loading
Loading